- Home
- Category
- Information Communication Network
- It Networks
- Network Security Appliances
- Unified Threat Management Utm Appliances
Showing 0 products
Frequently Asked Questions
What is included in a UTM appliance?
Firewall, intrusion prevention, antivirus, web filtering, application control and VPN as the core - with the exact list varying enough that it must be checked per product.
The firewall provides the stateful policy foundation. Intrusion prevention matches traffic against signatures of known attacks. Antivirus scans files in transit through web and mail traffic. Web filtering blocks categories of site. Application control identifies and permits or denies specific applications. VPN provides remote access and site-to-site tunnels.
Many add mail filtering, data loss prevention, wireless controller functionality, sandboxing for unknown files, and endpoint integration.
What differs between vendors is which of these are in the base product, which are in bundles, and which are separate - sandboxing and advanced malware analysis are commonly extra.
Compare on the specific functions needed rather than on the category name, and confirm the price includes them for the intended term rather than for a first year.
How much does enabling everything reduce throughput?
Substantially - commonly to between a fifth and a tenth of the headline figure, and less again with decryption.
Each engine inspects the same traffic in turn, and the deeper the inspection the more work per packet. Firewall throughput reflects forwarding with a policy applied; threat protection throughput reflects the same traffic passing intrusion prevention, antivirus and application identification.
Decryption is the largest single cost, and since most traffic is encrypted, inspecting content at all usually implies it.
The consequence is that sizing must start from the intended configuration. If the plan is full inspection with decryption on all internet traffic, the appliance must be sized against that figure and the internet circuit's peak rate.
Manufacturers publish these numbers, though not always prominently. Ask specifically for the threat protection and decrypted-inspection figures, and size for three years of growth rather than today's peak.
Is one appliance a single point of failure?
Yes, in both senses - availability and compromise - which is why high availability and a considered management path matter more here than on a single-function device.
If the appliance fails, the site loses its internet connection, its remote access, its inter-segment routing and its wireless control simultaneously. That argues strongly for a high-availability pair anywhere the site cannot be offline.
The compromise argument is that one device holds all the policy and all the credentials, so its management interface deserves particular protection: never reachable from the internet, multi-factor authentication for administrators, and administrative access restricted to a management network.
The counter-argument is worth stating too. Four separate devices are four attack surfaces, four update cycles and four consoles, and in a small team the practical result is that some of them are neglected. Consolidation with proper redundancy is usually the stronger position.
Who is a UTM appliance most suitable for?
Organisations with a single boundary, a modest circuit and a small team - which describes most small and mid-sized organisations and many individual sites of larger ones.
The fit is best where one device can genuinely cover the requirement: one internet connection, a few internal segments, remote access for staff, and no specialist requirement that demands a dedicated product.
It also fits branch sites of larger organisations, where a consolidated appliance managed centrally provides consistent protection without a specialist at every location.
Where it fits less well is at high throughput, where dedicated devices are more economical per gigabit; where a specific function must be best-in-class for regulatory or risk reasons; or where the security team is large enough to operate specialist tools properly.
Multi-site organisations should also weigh central management - administering thirty appliances individually removes much of the operational benefit unless the vendor provides a central console.
How are the subscriptions structured?
As annual bundles covering the update feeds, usually a significant recurring proportion of the hardware cost - and the appliance loses most of its value without them.
The firewall works without a subscription. Intrusion prevention signatures, antivirus definitions, web categorisation, application identification and reputation data all require one, and all become stale quickly.
Vendors package these differently: a basic bundle, a full bundle, and separately licensed extras such as sandboxing. Compare on what is actually needed, and get multi-year pricing where the appliance will be kept several years - it is usually discounted and it removes the risk of a lapse.
Set a reminder independent of the vendor's. A lapsed subscription frequently goes unnoticed because the device continues to pass traffic; the inspection simply stops improving, and then stops.
Include the renewal in the total cost when comparing products. A cheaper appliance with expensive subscriptions is not cheaper over five years.
Can it replace endpoint protection?
No. It covers a different part of the problem, and the two are complementary rather than alternative.
A network appliance sees traffic crossing its boundary. It cannot see anything that does not cross - a file from a USB device, activity between two machines on the same segment, or anything happening on a laptop working from home.
It also cannot see inside encrypted traffic without decryption, which is not applied to everything.
Endpoint protection sits where the code executes and sees behaviour regardless of how it arrived. It is the control that catches what the network missed.
The two work best together, and increasingly they integrate: several vendors let the appliance and the endpoint agent share intelligence, so a threat identified at one is blocked at the other, and an infected host can be quarantined from the network automatically.
Where budget forces a choice, endpoint protection is usually the more important, because it covers devices wherever they are - which since remote working became normal is much of the time.
What is the biggest configuration mistake?
Leaving features licensed but not enabled, or enabled but not tuned - so the appliance reports capability it is not delivering.
The common pattern is that the appliance is installed under time pressure, the firewall policy is configured because nothing works without it, and the inspection features are left for later. Later does not arrive.
The second pattern is enabling intrusion prevention in detection mode to avoid breaking anything, and never moving it to prevention. It then generates alerts nobody reads and blocks nothing.
The third is web filtering configured with default categories that do not match the organisation's policy, producing complaints that are resolved by broad exceptions until the filtering is effectively off.
The remedy in each case is a deliberate commissioning plan: enable one function at a time, tune it over a couple of weeks, move it from detection to prevention, then start the next. That takes longer than the installation but it is what turns the purchase into a control.